Use Casdoor as the authorization server of an MCP server
The Model Context Protocol (MCP) specification separates the authorization server from the MCP server, which is the resource server. Your MCP server doesn't have to sign users in or issue tokens: it points clients to an authorization server and validates the tokens that the authorization server issues. Casdoor can be that authorization server.
This section explains how to set this up. To manage Casdoor itself from an MCP client, see the MCP server of Casdoor instead.
How the parts work together
What Casdoor provides
The authorization server of an MCP server has to implement several standards. Casdoor implements all of them:
| Standard | Endpoint or feature |
|---|---|
| RFC 8414: OAuth 2.0 Authorization Server Metadata | /.well-known/oauth-authorization-server |
| OpenID Connect Discovery | /.well-known/openid-configuration |
| RFC 7591: Dynamic Client Registration | /api/oauth/register |
| RFC 7636: PKCE | Authorization code flow |
| RFC 8707: Resource Indicators | Tokens whose audience is your MCP server |
| RFC 7517: JSON Web Key Set | /.well-known/jwks, for token validation |
Casdoor also provides what surrounds these standards:
- Sign-in: Passwords, single sign-on, multi-factor authentication, WebAuthn, and Face ID
- Users: Organizations, roles, permissions, and the user directory
- Consent: A consent screen that lists the requested scopes with their descriptions
- Tokens: JSON Web Token (JWT) issuance, refresh tokens, and token introspection
- Custom scopes: Permissions that you define for your tools. See Define custom scopes
- Application categories: The category
Agentwith the typeMCP. See Application categories - Self-hosting: Casdoor is open source under the Apache 2.0 license and runs on your own infrastructure
What your MCP server does
- Publish Protected Resource Metadata: Return a JSON document at
/.well-known/oauth-protected-resourcethat names Casdoor as the authorization server. - Challenge unauthenticated requests: Answer them with HTTP 401 and a
WWW-Authenticate: Bearerheader. - Validate tokens: Verify the signature of each JWT with the JWKS of Casdoor.
- Check the audience: Check that the
audclaim of the token is the resource URI of your server. - Enforce scopes: Check that the token contains the scope that each tool requires.
Your server needs no user database, no password storage, no session management, and no OAuth 2.0 endpoints of its own.
Get started
- Install Casdoor, or use Casdoor Cloud.
- Configure Casdoor and your MCP server.
- Add the token validation to your server, with examples in Python, Node.js, and Go.
See also
- MCP authorization specification
- Register clients dynamically
- OAuth 2.0
- Casdoor pull requests that added these features: #5092 (Protected Resource Metadata), #5094 (metadata), #5097 (DCR), #5098 (resource indicators), #5100 (consent)